THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86120 (MEDIUM 4.3) — APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets the

[NVD] CVE-2026-86120 (MEDIUM 4.3) — APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets the

mednvdPublished 2026-09-05

CVE-2026-86120 CVSS: 4.3 MEDIUM Published: 2026-09-05T10:16:43.307

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploitin

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86120